Swappa.com for GrapheneOS compatible devices – Stay Away
discuss.grapheneos.org
discuss.grapheneos.org
Ohhhh, is that how it works? Maybe I should try that next time. Instead of selling broken hardware as "NOT TESTED, AS IS, PARTS MACHINE" I should sell them as "100% working!" and when someone asks, I'll tell them "sorry, it's not feasible to search through all devices and find the working ones"
Go make a stink about it at the customer service desk and they will probably say exactly that.
Source: I ditched the techpocalypse at the end of 2024 and now happily work at a grocery store.
Facebook Marketplace almost all of phone for sale is locked/stolen or the person selling does not know originator (f.e. Verizon phone never unlockable, includes all reseller) and often they are too non technical to know if it was bought from google play store ("factory unlocked") Often it will not even be paid off or intentional to scam you with a phone that will work for a month until it is reported stolen and unpaid loan
Their About page says:
> The inspiration for Swappa sparked when Ben had trouble finding a good source for test devices for Android development projects.
> Devices sold in partnership with specific carriers may be locked by the carrier, which will prevent installing GrapheneOS. This is primarily an issue with US carriers and isn't common elsewhere in the world. To avoid this, either don't buy a carrier device, or make sure it can be unlocked.
I only buy used devices from online marketplaces/vendors with free returns, as it keeps the incentives aligned such that sellers don't want to hide defects (as it just increases their return rate).
The easy way is to search for ones for which the seller explicitly says "OEM" or "bootloader" unlockable/unlocked (or seller says it already has "grapheneos", "graphene", "calyxos", etc., installed).
For awhile, I came up with some tricks to try to get a better price by identifying ones that were bought directly from Google (rather than through a carrier, which are who has been disabling bootloader unlocking thus far), but decided it wasn't worth the effort.
Of course, you can also just buy a new one from Google.
Swappa staff were unhelpful and only after I opened a dispute with Paypal did I get my money back.
I don't blame Swappa for a random dodgy seller, but this was an "Enterprise" seller, whom is still selling on Swappa today!
See this reddit review, which isn't mine, but is almost exactly what I dealt with.
https://reddit.com/r/Scams/comments/1d8emzf/suckered_on_swap...
Reading OP's post, I can't help but wonder if they bought a Verizon Pixel. This is a very very well-known gotcha. Verizon locks their bootloaders and you can't bootloader-unlock Verizon Pixels, even after they are carrier-unlocked.
So I bought an “unlocked” Pixel that had a locked bootloader. Returned it. Felt bad because the seller correctly classified it.
Ultimately I found an eBay seller (thegizmotrader) that explicitly lists the bootloader as unlockable.
When buying secondhand, I suggest looking for Pixels not associated with any particular carrier (as are sold by Google online store), and especially not Verizon.
I feel like eBay put a lot of work into creating a competitive marketplace where honesty was rewarded, and it basically works well but they got an unsavory reputation anyways. Then Amazon tried to hide that complexity from the end user and buyers just get burned. Maybe Swappa is trying to go the Amazon route? I do not think there are real shortcuts here. Either the marketplace needs to vet sellers manually, or offer a competitive, transparent reputation system like eBay.
I generally trust private sellers a lot more than professional ones, if you vet them well enough (check their page, check their reviews, check their other listings), the chance that you'll get a good deal on a device in the condition described. The incentive to gain a profit is a whole lot lower, a commercial seller has to make sure they're the winner in some way during a transaction, they have bills, staff and assets. A private person is often happy to just get rid of the phone, as it would usually rot in the old phone drawer, until it eventually ends up in an e-waste bin a decade later when they clean out. Getting a little money back is already a win. Surprisingly, I've never had a bad experience. I presume there's also buyer protection, but I'm hoping I never have to use it.
This has a downside like your scenario, but also a positive side when you find gems in used markets but the owner doesn’t know its potentials.
In UK, my credit card was my transit card. I find it easier to navigate my physical wallet than a phone for such things. Personal opinion.
In any case, banking apps that don't function on graphene should be embarrassed by their stupidity. Amex forces sms/email 2fa to login on my graphene phone, when chase, fidelity and several other bank apps do not.
So it’s actually kind of a real thing
Having said that, a successful car infotainment system attack on android auto or apple carplay could, of course, compromise your phone.
So it's up to you whether you decide to cope with that possibility by breaking the law and navigating with a handheld device, or simply declining to do banking on your phone, since successful car exploits mean the attack surface against your phone is much larger than you might presume.
I was responding to a comment about the security implications of letting the infotainment system interact with the vehicle controls, and I referenced an incident where someone compromised a car via that.
I have no idea how CarPlay would compromise your phone given apples sandbox but whomever finds it is gonna have a multimillion dollar payday since iOS jailbreaks are quite valuable.
> Paying with your phone just seems like one of those separation of concerns problem.
Followed by:
> You could then separate the audio system from your car and drive around with a boombox
The first discusses behaviors of end-users. The second was a lame attempt to take the mickey of that, which is why my response clearly indicated that, to my knowledge there are zero security implications of playing your music through your car's entertainment system.
This remains true.
You are discussing design flaws, not user behavior flaws, which is why I pointed out that the design flaws you bring up, in addition to doing you bodily harm, could conceivably also be part of an exploit chain that validates the original poster's concern about using his phone for banking.
But I still sincerely doubt that the choice of playing Beethoven or Iron Maiden either directly places you at risk*, or makes a difference to the ease of exploiting any design flaws in your vehicle.
IOW, the first behavior given (not using your phone for banking) is easy to construe as prophylactic, given that, yes, in fact, peoples' credentials have been stolen from their phones and bad things have happened, due to using phones for financial transactions.
The second behavior given (use a boombox instead of your car's audio) of course could theoretically alter outcomes, but to my knowledge, there has never been a car exploit that depends on whether you have fiddled with the volume control or station selector.
* Assuming of course, that your volume isn't so loud that you've riled up other people. That's always a risk.
Even my 2015 Mazda has enough vehicular settings in the infotainment menu that despite being replaceable with a double-din I haven't bothered because I'd lose all configurability there. I opted for a cheapo $100 carplay unit instead - the modern equivalent of the discman-to-tape adapters ;)
I also dont think everything needs to be an app.
These days I just care so much about "things should just work" that I cannot justify doing this. I cannot think about how I could spend time figuring out what to do when the repo is no longer maintained or something breaks for random reasons.
and if you did you could use curve pay instead. Basically the same thing with more features, the only catch is that they charge FX fees after surpassing a limit (but that can be mitigated by paying with the same currency of your linked card, thus never executing a change in the first place)
also my bank apps install, but yes, no tap to pay
My tiny local credit union app isn't on there, but it worked fine. I miss wallet a bit and it's a shame that there are important apps which still refuse to act reasonably, but I don't think it's really that bad.
As a side note, I've been using it for a few months now, and it works great. All the apps I use run on it just fine. Battery life is great, and you don't have a bunch of cruft from Google running on your device. Can highly recommend for anybody looking for a phone you actually own.
I had issues with receiving incompatible "variants" of compatible devices when shopping for used phone for custom roms